Remote onboarding removes the physical cues that once helped staff spot fraud. Liveness checks and deepfake detection help confirm that a real person is present at capture time and that the submitted image is not replayed or generated. Without those controls, fraudsters can scale impersonation attempts, reuse stolen credentials, and pass verification with far less friction.
Why remote onboarding raises the bar for verification
Remote onboarding changes the threat model because the organisation no longer has a trusted physical interaction to rely on. Face-to-face checks, desk-side supervision, and visible cues of hesitation disappear, so the verification process has to prove more than document possession. It must establish that a live person is present, and that the capture has not been replayed, injected, or synthetically generated.
That is why liveness checks matter: they test whether the biometric sample is being presented by a real person in the moment, rather than from a photo, screen replay, mask, or injected feed. Deepfake detection matters for the same reason, but at the media layer. It helps identify manipulated video or voice that can defeat human judgement during onboarding.
Remote onboarding also tends to compress decisions into a few digital steps. That makes identity proofing controls part of the first security boundary, not a nice-to-have later in the journey. When the capture channel is weak, a fraudster can present a convincing but false identity, then use that access to open accounts, request services, or seed downstream abuse.
What liveness and deepfake controls actually change
Liveness checks are designed to answer a narrow but important question: is the subject in front of the camera a live human, or a reproduction of one? Depending on the implementation, they may use motion, texture, challenge-response, or camera-injection detection to reduce spoofing risk. Deepfake detection addresses a different failure mode, where a synthetic face or voice can look plausible enough to satisfy either software checks or a human reviewer.
These controls are most valuable when they sit alongside stronger identity proofing rather than replace it. A document check can confirm that a passport or ID card looks legitimate, but it does not prove the applicant is the rightful holder. A liveness signal can confirm presence, but it does not by itself establish identity. The practical value comes from combining document validation, presence checks, and policy-based review thresholds.
That combination is especially important because attackers adapt. If one control is easy to bypass, fraud shifts to the weakest point in the workflow. The aim is not to make onboarding perfect, it is to raise the cost of impersonation enough that fraud at scale becomes harder, slower, and more detectable.
Where remote onboarding breaks down if you rely on humans alone
Human reviewers are still useful, but they are poor at consistently detecting synthetic media when the sample is brief, low quality, or time pressured. A convincing deepfake can exploit attention, authority bias, and process fatigue, especially when the reviewer expects a normal customer or employee journey. Remote onboarding also creates reuse risk, because stolen documents, recorded video, or captured credentials can be replayed across multiple attempts.
That is why the control objective should be to reduce both false acceptance and scalable fraud. In practice, liveness and deepfake detection help limit three common failure modes: replay attacks, injected video or camera feeds, and synthetic impersonation that passes as genuine interaction. They are most effective when the organisation treats onboarding as a verification workflow with step-up controls, not as a single yes or no event.
For a deeper treatment of why document checks alone are insufficient, NHIMG’s Identity Proofing and KYC Guide covers liveness detection, synthetic identity fraud, and remote identity proofing in one workflow. Deepfakes, Social Engineering and AI Impersonation Guide is also useful where video or voice impersonation is part of the attack path.
Risk and Threat Considerations
Remote onboarding creates a higher fraud exposure because the attacker only needs to defeat a digital decision point once, then can reuse the resulting account or access. The same weaknesses that help an impostor pass identity proofing can also help them evade downstream controls, especially if the organisation accepts weak signal quality or over-trusts a polished video interaction.
Failure mechanism: The attacker uses replayed video, injected camera output, synthetic voice, or stolen identity material to satisfy the onboarding step without being physically present. If the control stack lacks strong liveness testing, deepfake detection, and review escalation, the fraud path becomes repeatable at scale.
Impact: Successful impersonation can lead to account opening fraud, credential abuse, payment diversion, or longer-term account takeover, with the initial onboarding decision becoming the entry point for later misuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Remote onboarding and liveness checks directly concern identity proofing assurance. |
| Recommendation — Use assurance levels and identity proofing requirements to set the strength of remote verification. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Remote onboarding of customers or external users depends on authenticating non-organizational identities. |
| IA-12 — Identity Proofing | Liveness and deepfake checks are part of proofing a remote applicant's identity. | |
| Recommendation — Apply IA-8 to verify external users before issuing access or account privileges. Apply IA-12 to strengthen remote identity proofing against impersonation and replay. | ||
| GDPR | A.5.1 — Processing of special category data | Biometric onboarding data can trigger heightened privacy obligations under GDPR. |
| Recommendation — Minimise biometric collection and document lawful basis and retention for onboarding data. | ||
Practitioner Guidance
What to prioritise: Treat liveness and deepfake detection as control layers for remote identity proofing, not as standalone fraud filters. The stronger the downstream privilege or financial exposure, the less acceptable it is to rely on a single biometric signal.
What to verify: Confirm that the workflow can detect replay, injection, and synthetic media, and that borderline cases are routed to manual review or step-up verification. If your tooling cannot explain why a sample passed, you should not treat it as a trusted decision.
Common mistake: Teams often overestimate the value of a good-looking video call and underestimate how quickly fraudsters can industrialise the same tactic across many attempts. The right question is not whether the image looked real, but whether the full onboarding process can resist a determined impersonation campaign.
Practitioner takeaway: Remote onboarding is where verification must do the work that physical presence used to do, so the control objective is to make impersonation expensive, not merely inconvenient.
Related resources from NHI Mgmt Group
- Why do real-time account checks matter when onboarding users in regulated markets?
- When should organisations add liveness and deepfake detection to onboarding controls?
- Why does liveness detection matter for remote onboarding and authentication in high risk environments?
- How should security teams design liveness checks so they resist spoofing and deepfake attempts without adding too much friction for legitimate users?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org